πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27919 β€Ό

Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27906 β€Ό

Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has to know one of the configured Odette IDs of the OFTP2 server. An attacker can upload files to the server outside of the intended upload directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26659 β€Ό

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24643 β€Ό

A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26197 β€Ό

Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27920 β€Ό

libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25523 β€Ό

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44905 β€Ό

Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1071 β€Ό

User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26198 β€Ό

Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26620 β€Ό

Akeo Consulting Rufus Executable 3.17.1846 and Rufus Portable Executable 3.17p were discovered to allow attackers to execute arbitrary code or escalate privileges via placing a crafted x86 DLL in the same directory as other executables.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26200 β€Ό

Technitium Installer v4.4 was discovered to allow attackers to execute arbitrary code or escalate privileges via placing a crafted DLL in the same directory as the current installer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26205 β€Ό

Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27948 β€Ό

Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26245 β€Ό

Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1106 β€Ό

use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ F-Secure launches WithSecure, spinning off entire enterprise portfolio πŸ“’

After years of trying to integrate business and consumer streams, F-Secure signals a complete split will help both new entities focus on their customers and industry relevance

πŸ“– Read

via "ITPro".
πŸ“’ The keys to catching a cyber crook πŸ“’

Why greed, carelessness and an itch for glory are highly exploitable chinks in a cyber criminal's armour

πŸ“– Read

via "ITPro".
πŸ“’ EU proposes new bloc-wide cyber security regulations πŸ“’

The Computer Emergency Response Team for the EU institutions, bodies, offices, and agencies (CERT-EU) will be renamed as the β€˜Cybersecurity Centre'

πŸ“– Read

via "ITPro".
πŸ“’ Linux botnet spreads using Log4Shell flaw πŸ“’

The malware uses DNS tunnelling to communicate with its C2 control server

πŸ“– Read

via "ITPro".
πŸ“’ How a platform approach to security monitoring initiatives adds value πŸ“’

Integration, orchestration, analytics, automation, and the need for speed

πŸ“– Read

via "ITPro".